RE: [PHP] Re: [PHP-DEV] cookies and sessions security

From: Date: Mon, 15 Jan 2001 03:26:47 +0000
Subject: RE: [PHP] Re: [PHP-DEV] cookies and sessions security
Groups: php.general 
Request: Send a blank email to php-general+get-34550@lists.php.net to get a copy of this message
> Very good: keep the thing on a secure connection all the time, set a > session id cookie and keep all user info (possibly including remote ip) > in the server's session db... (vulnerable to nothing I can think > of at the moment...) > > There are probably more things you could do I haven't thought > of... but this oughta be a decent start ;) Suggestion, don't send session IDs as cookies, since they may be sequential and guessable. Instead, grab an MD5 of the session ID, the remote IP address, and the current time. Throw as much entropy in there as you can, send the MD5 sum as the cookie value, and store it in the session table in the database. Jason -- Jason Murray jasonm@melbourneit.com.au Web Design Team, Melbourne IT Fetch the comfy chair!

« previous php.general (#34550) next »